imtoken will never ask for your seed phrase, private key or verification code. Always review the address, network and request details before transferring, signing or approving.
imtoken
Home / Phishing & Scams
imtoken

Phishing & Scams

A practical imtoken guide to look-alike domains, fake support, fake airdrops and clipboard attacks, with clear checks for network, permissions and security.

Download imtoken

Core concepts

Seed phrases and private keys remain under the user’s control. Official staff will not ask for them, and they should never be sent through chat, email or web forms. In the context of look-alike domains, it also helps to connect fake support with fake airdrops rather than treating them as isolated features. Before transferring, signing or approving, review the domain, address, network, amount, target contract and permission scope. Keep the actual request details visible, and stop if the network, contract or permission cannot be explained clearly.

A useful review habit is to compare look-alike domains with the active network state and the exact request shown by the wallet. Third-party DApps and smart contracts may introduce their own risk, and confirmed on-chain transactions usually cannot be reversed by the wallet alone.

Practical workflow

Before transferring, signing or approving, review the domain, address, network, amount, target contract and permission scope. In the context of fake support, it also helps to connect fake airdrops with clipboard attacks rather than treating them as isolated features. Public computers, remote-control sessions, unknown Wi-Fi and untrusted apps increase exposure around sensitive actions. Keep the actual request details visible, and stop if the network, contract or permission cannot be explained clearly.

A useful review habit is to compare fake support with the active network state and the exact request shown by the wallet. Third-party DApps and smart contracts may introduce their own risk, and confirmed on-chain transactions usually cannot be reversed by the wallet alone.

Keep secrets offline
Verify every request
Limit permissions
Review after use

Checks before confirmation

Public computers, remote-control sessions, unknown Wi-Fi and untrusted apps increase exposure around sensitive actions. In the context of fake airdrops, it also helps to connect clipboard attacks with look-alike domains rather than treating them as isolated features. After use, review DApp sessions and approvals and consider removing permissions that are no longer needed. Keep the actual request details visible, and stop if the network, contract or permission cannot be explained clearly.

A useful review habit is to compare fake airdrops with the active network state and the exact request shown by the wallet. Third-party DApps and smart contracts may introduce their own risk, and confirmed on-chain transactions usually cannot be reversed by the wallet alone.

Review checklist

  • Seed phrases and private keys remain under the user’s control. Official staff will not ask for them, and they should never be sent through chat, email or web forms.
  • Before transferring, signing or approving, review the domain, address, network, amount, target contract and permission scope.
  • Public computers, remote-control sessions, unknown Wi-Fi and untrusted apps increase exposure around sensitive actions.
  • After use, review DApp sessions and approvals and consider removing permissions that are no longer needed.

Risks and follow-up

After use, review DApp sessions and approvals and consider removing permissions that are no longer needed. In the context of clipboard attacks, it also helps to connect look-alike domains with fake support rather than treating them as isolated features. Seed phrases and private keys remain under the user’s control. Official staff will not ask for them, and they should never be sent through chat, email or web forms. Keep the actual request details visible, and stop if the network, contract or permission cannot be explained clearly.

A useful review habit is to compare clipboard attacks with the active network state and the exact request shown by the wallet. Third-party DApps and smart contracts may introduce their own risk, and confirmed on-chain transactions usually cannot be reversed by the wallet alone.

Key risks

  • Never share a seed phrase, private key or verification code.
  • Third-party DApps, networks and contracts can fail or behave maliciously.
  • Staking and digital assets do not offer guaranteed returns or protection from price volatility.